Managed XDR

vtdl_j3du7xs0 — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
vtdl_j3du7xs0
Тип файла
MS Windows shortcut, Item id list present, ctime=Tue Sep 10 10:27:03 2024, mtime=Tue Sep 10 10:27:03 2024, atime=Tue Sep 10 10:27:03 2024, length=0, window=hide
Размер файла
1.1 KB
Первое обнаружение
Последнее обнаружение

Окружение

win7/x86 en

Хеши

SHA1
a8fbb1edd353812c3b8fa44d749687671316a4d7
SHA256
04a8c9986ca47dae924ccd324d5ffad7e3caefdae5e1030a53fe55f52dfb3ae5
MD5
98094651bbcfea804c5159755238b39f

Сигнатуры

Privilege Escalation

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Defense Evasion

T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process

Other

yara_rules: Static rules
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process